If your WordPress site is showing unfamiliar admin users, redirecting visitors to spam sites, or flagged by Google Safe Browsing, start with a scan, not a full reinstall. Flashcloud runs Imunify360 at the server level on every hosting account, which already screens for known malware signatures and blocks a lot of attacks before they land. What's left to check is application-level: your WordPress files, database, and plugins for anything that slipped through or was planted via a compromised plugin or weak password.
Work through the checks below in order. Most infections show up in the first two steps without needing a dedicated scanner plugin.
Check the obvious signs first
Before installing anything, look for the common tells:
- Unfamiliar admin users. Open
wp-admin → Usersand check every account with Administrator role. Malware often creates a hidden admin account as a backdoor. - Unexpected plugins or themes. Check
wp-admin → Pluginsandwp-admin → Appearance → Themesfor anything you didn't install. Attackers sometimes drop a disguised plugin with a generic name like "WP Cache Helper." - Modified core files. Go to
wp-admin → Dashboard → Updatesand click "Re-install Now" next to your current WordPress version. This overwrites core files with clean copies without touching your content, and it's the fastest way to rule out core file tampering. - Search engine or browser warnings. Search
site:yourdomain.comin Google, or checkwp-admin → Tools → Site Healthfor security-related flags. See WordPress Site Health warnings and which ones matter for which warnings are worth chasing.
Back up before you touch anything
Take a fresh backup before you start removing files or plugins, even though the site is already compromised. You want a point-in-time copy in case a cleanup step goes wrong, and you want the infected copy preserved in case you need to compare file timestamps later. Automatic backups run on most hosting accounts, so you likely have a recent restore point to fall back on if things get worse.
Use a malware scanner plugin when you need to go deeper
If the manual checks above don't turn up anything obvious but you still suspect an infection, a dedicated scanner plugin checks file integrity against known-good WordPress core, theme, and plugin signatures, and flags suspicious code patterns manual review would miss.
- Install a reputable scanner (Wordfence and Sucuri Security are the two most widely used) from
wp-admin → Plugins → Add New. - Run a full scan, not a quick scan. Full scans check file contents against the original plugin and theme repositories, not just file existence.
- Review every flagged file individually before deleting. Scanners flag modified core files, but also flag legitimate customizations, like a child theme's
functions.php, as a false positive. Don't mass-delete without checking. - For infected files inside WordPress core, theme, or plugin folders, replace them by reinstalling that specific plugin or theme fresh rather than trying to hand-edit out the malicious code. It's faster and you know the result is clean.
- For files that don't belong to any known plugin or theme (random PHP files in
wp-content/uploads, for example), delete them directly through the File Manager tile on your service page in the portal, or via File Manager in cPanel.
Close the door it came in through
Scanning and cleaning fixes the symptom. If you don't close the entry point, it comes back. The most common causes:
- Outdated plugins or themes. Old versions with known vulnerabilities are the number one infection vector. Update everything, and remove plugins and themes you're not actively using instead of leaving them installed and inactive.
- Weak admin passwords. Reset every administrator password after a cleanup, not just the one you think was compromised.
- Nulled or pirated plugins/themes. Free copies of premium plugins from non-official sources are a common way malware gets installed intentionally. Replace them with licensed originals.
Once you're confident the site is clean, test everything on a copy before you consider the job finished on a busy or revenue-generating site. See Using WordPress staging to verify plugin and theme updates don't break anything, especially if you're running a WooCommerce store where a broken checkout after cleanup costs real sales.
When to contact support
If you've run a full scanner scan and still see reinfection within a day or two, or if the site is completely inaccessible and you can't get into wp-admin at all, open a ticket from Support → New ticket in the portal. Persistent reinfection usually means something wasn't fully removed, like a scheduled task or a backdoor file outside the normal plugin/theme folders, and that's worth a second set of eyes from a real person rather than repeated scan-and-delete cycles.